Apple fixes new zero-day used in attacks against iPhones, iPads

Gandalf_The_Grey

Level 76
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 24, 2016
6,576
In security updates released on Monday, Apple has fixed the ninth zero-day vulnerability used in attacks against iPhones since the start of the year.

Apple revealed in an advisory today that it's aware of reports saying the security flaw "may have been actively exploited."

The bug (CVE-2022-42827) is an out-of-bounds write issue reported to Apple by an anonymous researcher and caused by software writing data outside the boundaries of the current memory buffer.

This can result in data corruption, application crashes, or code execution because of undefined or unexpected results (also known as memory corruption) resulting from subsequent data written to the buffer.

As Apple explains, if successfully exploited in attacks, this zero-day could have been used by potential attackers to execute arbitrary code with kernel privileges.

The complete list of impacted devices includes iPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and later.

Apple addressed the zero-day vulnerability in iOS 16.1 and iPadOS 16 with improved bounds checking.
 

Gandalf_The_Grey

Level 76
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 24, 2016
6,576
Apple Releases iOS 16.1, iPadOS 16.1 and macOS Ventura
Apple has just released iPadOS 16.1 and macOS Ventura alongside iOS 16.1. If the latter is a minor update that follows the release of iOS 16 last month, iPadOS 16.1 and macOS Ventura are two major updates for iPad and Mac users.

This year, Apple chose to delay the release of iPadOS 16 to October, which is why the version we get today is iPadOS 16.1 instead of iPadOS 16.0. If iOS and iPadOS still share a lot of code, the latter is getting a new Stage Manager feature that’s also available on macOS Ventura.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top